Security News

Google Chrome to allow users to add notes to saved passwords
2022-02-22 19:46

Google is testing a new Chrome feature that allows users to add notes on passwords saved in the web browser. The new feature was spotted by a Reddit user on Google Chrome Canary, which is an experimental future version three releases away from the stable branch, currently at version 98.

Xenomorph Malware Burrows into Google Play Users, No Facehugger Required
2022-02-22 18:00

An Android trojan dubbed Xenomorph has nested in Google Play, already racking up more than 50,000 downloads from the official app store, researchers warned. The malware is also a flexible, modular banking trojan, which has code overlaps and other ties to the Alien malware - hence the name.

New Android Banking Trojan Spreading via Google Play Store Targets Europeans
2022-02-21 21:18

A new Android banking trojan with over 50,000 installations has been observed distributed via the official Google Play Store with the goal of targeting 56 European banks and carrying out harvesting sensitive information from compromised devices. Xenomorph, like Alien and ERMAC, is yet another example of an Android banking trojan that's focused on circumventing Google Play Store's security protections by masquerading as productivity apps such as "Fast Cleaner" to trick unaware victims into installing the malware.

Google Drive flags macOS '.DS_Store' files for copyright violation
2022-02-18 09:10

DS Store' files generated by macOS file systems as a violation of its copyright infringement policy. DS Store" file on their Google Drive being flagged for violating Google's 'Copyright Infringement' policy.

Google Bringing Privacy Sandbox to Android to Limit Sharing of User Data
2022-02-17 19:18

Google on Wednesday announced plans to bring its Privacy Sandbox initiatives to Android in a bid to expand its privacy-focused, but also less disruptive, advertising technology beyond the desktop web. "The Privacy Sandbox on Android builds on our existing efforts on the web, providing a clear path forward to improve user privacy without putting access to free content and services at risk," Anthony Chavez, vice president of product management for Android security and privacy, said.

Google expands Privacy Sandbox to Android
2022-02-17 03:01

Google plans to extend its rework of web ad technology - the optimistically named Privacy Sandbox - to Android devices in an effort to limit the misuse of data in its mobile ecosystem. It began to take shape a year after Google undertook Project Strobe, a rethink of Google Account and Android data access in the wake of ongoing security and privacy problems.

Google almost doubles Linux Kernel, Kubernetes zero-day rewards
2022-02-15 20:38

Google says it bumped up rewards for reports of Linux Kernel, Kubernetes, Google Kubernetes Engine, or kCTF vulnerabilities by adding bigger bonuses for zero-day bugs and exploits using unique exploitation techniques. "We increased our rewards because we recognized that in order to attract the attention of the community we needed to match our rewards to their expectations," Google Vulnerability Matchmaker Eduardo Vela explained.

Google announces zero-day in Chrome browser – update now!
2022-02-15 19:17

In the past few days, both Apple and Adobe have published software updates to close off zero-day security holes that were already being exploited by attackers. In other words, now matter how quickly you update against a zero-day once the patch is announced, you know that someone - and you have to hope that it wasn't you! - has already been attacked and pwned, even if they're accustomed to patching promptly themselves.

Google Chrome emergency update fixes zero-day exploited in attacks
2022-02-14 23:34

Google has released Chrome 98.0.4758.102 for Windows, Mac, and Linux, to fix a high-severity zero-day vulnerability used by threat actors in attacks. It is possible to install the update immediately simply by going into the Chrome menu > Help > About Google Chrome.

Linux tops Google's Project Zero charts for fastest bug fixes
2022-02-14 13:04

The bug hunters at Google's Project Zero team have released their latest time-to-fix data and Linux is smashing the opposition. Between 2019 and 2021 open-source developers fixed Linux issues in an average of 25 days, compared to 83 for Microsoft and Oracle pulling last place at 109 days, albeit from a very low number of cases.